Amazon EKS for Cloud Engineers
Learn Amazon EKS end to end: create clusters with eksctl and Terraform, give pods AWS access, add load balancers and storage, and upgrade safely.
What You'll Learn
Understanding What Amazon EKS Manages and What You Own
It is 11:40 on a Friday night at acme-shop.
Preparing Your Workstation and AWS Account for EKS
Most failed EKS labs fail before the first command that matters: an old kubectl, a missing tool, or credentials for the wrong account.
Creating an EKS Cluster with eksctl
eksctl is the official command-line tool for EKS.
Building the Same Cluster with Terraform
eksctl is the fastest way to learn. Terraform is how most teams keep EKS clusters long term, because the cluster, VPC, IAM roles, and DNS all live in...
Choosing Compute: Managed Node Groups, Fargate, Karpenter, and Auto Mode
Pods need somewhere to run. EKS offers four ways to provide that compute, and the choice decides how much node management you do, how fast scaling...
Controlling Who Can Use the Cluster with Access Entries
Every kubectl call to EKS is authenticated with IAM and then authorized by Kubernetes.
Skills You'll Master
Curriculum Index14 topics
Understanding What Amazon EKS Manages and What You Own
It is 11:40 on a Friday night at acme-shop.
Preparing Your Workstation and AWS Account for EKS
Most failed EKS labs fail before the first command that matters: an old kubectl, a missing tool, or credentials for the...
Creating an EKS Cluster with eksctl
eksctl is the official command-line tool for EKS.
Building the Same Cluster with Terraform
eksctl is the fastest way to learn. Terraform is how most teams keep EKS clusters long term, because the cluster, VPC...
Choosing Compute: Managed Node Groups, Fargate, Karpenter, and Auto Mode
Pods need somewhere to run. EKS offers four ways to provide that compute, and the choice decides how much node...
Controlling Who Can Use the Cluster with Access Entries
Every kubectl call to EKS is authenticated with IAM and then authorized by Kubernetes.
Giving Pods AWS Access with EKS Pod Identity
Pods often need AWS APIs: cart-service reads S3, a worker reads SQS, the EBS driver creates volumes.
Exposing Applications with the AWS Load Balancer Controller
A Kubernetes Service of type ClusterIP is only reachable inside the cluster.
Adding Persistent Storage with the EBS CSI Driver
Containers lose their files when they restart.
Upgrading EKS Clusters Safely
Kubernetes releases a new minor version roughly three times a year, and EKS follows.
Controlling EKS Cost and Tearing Down Cleanly
EKS cost surprises come from three places: resources running when nobody needs them, resources created by Kubernetes...
Running the Lab: Building and Exposing cart-service on EKS
In this lab you build acme-shop's first EKS cluster, put cart-service behind a real ALB, give it persistent storage...
Running the Lab: Storage, Pod Access, and Teardown
The cluster from the previous topic is still running and billing, so continue straight on.
Reviewing EKS: Quick Reference, Common Mistakes, and Next Steps
Quick reference Common mistakes Putting application permissions on the node role.
Career Impact
Roles that use the skills in this module.
DevOps Engineer
Site Reliability Engineer
Platform Engineer
Cloud Engineer
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
No. Every EKS cluster pays an hourly control plane fee from the moment it exists, plus the EC2 nodes, NAT gateway, and load balancers it uses. A short lab costs a few US dollars if you delete the cluster the same day, and much more if you forget it.
Learn eksctl first because it shows you every moving part with one config file. Use Terraform for clusters your team keeps, because it versions the whole stack, VPC included, next to the rest of your infrastructure.
Both give a pod its own IAM role instead of borrowing the node's role. Pod Identity is the newer method: no OIDC provider per cluster and a simpler trust policy. IRSA is the older method you will still meet, and it is the one that works on Fargate.
Each Kubernetes version gets 14 months of standard support on EKS, then 12 months of extended support at a much higher hourly price. In practice, plan one minor version upgrade every few months so you never fall into extended support by accident.